Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open
wiz.io | blog | #rce | #teamcity | #misconfiguration | #honeypot | #cryptomining | #wiz-research | #jdwp
Summary
Wiz Research documents an intrusion via an exposed JDWP debug port: attackers went from a TeamCity honeypot to RCE in hours, planting a modified XMRig miner with persistence and mining-pool proxies.
- Published
- Collected
Skip to content